Slides and demo video from my talk at CyBe AI Summit 2026 (4th Sept, Bangalore) on Excessive Agency in context of AI Agent Execution - reconstructed from a real pentest where a “helpful” AI agent was the door in, chaining a debug tool, container access, a neighbouring internal agent, and overprivileged AWS IMDS creds into full cloud account compromise.
Wiring a Wi-Fi smart bulb into Claude Code’s hook system so it turns green while Claude works, red when it needs me, and white when it’s idle - no terminal glance required.
My take on using different models for different projects via Claude Code with some simple shell scripting and API Keys. Not as elegant as a model router but works very well for everyday tasks.
Writeup of a bug I found with Google Gemini for Gmail that allows for calendar entries to be created within victim calendars and also allows for Gemini to leak it’s system prompt by following instructions embedded in email body triggered when tools like summarization are called to operate on email threads.
Slides and some background of my talk at Vulncon Bangalore (June 2026) on how I convinced Amazon Q to perform an authorization check on itself, its tools and the results of that exploration. Interesting findings overall around IAM boundaries and tool/capability privileges.